VYPR

Vendor CVEs

Copeland

All CVEs

32 total · sorted by risk
  • CVE-2026-21718CriFeb 27, 2026
    risk 0.65cvss 10.0epss 0.00

    An authentication bypass vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, enabling any attackers to bypass the authentication requirement and achieve pre-authenticated code execution on the system.

  • CVE-2025-6519CriSep 2, 2025
    risk 0.64cvss 9.8epss 0.01

    E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user.

  • CVE-2025-52549CriSep 2, 2025
    risk 0.64cvss 9.8epss 0.00

    E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters.

  • CVE-2026-24663CriFeb 27, 2026
    risk 0.59cvss 9.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting malicious input into the…

  • CVE-2026-25085HigFeb 27, 2026
    risk 0.56cvss 8.6epss 0.00

    A vulnerability exists in Copeland XWEB Pro version 1.12.1 and prior, in which an unexpected return value from the authentication routine is later on processed as a legitimate value, resulting in an authentication bypass.

  • CVE-2026-3037HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by modifying malicious input injected into the MBird SMS service URL and/or code via the utility route which is…

  • CVE-2026-25721HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the server username and/or password fields of the restore action in the API…

  • CVE-2026-25196HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the Wi-Fi SSID and/or password fields can lead to remote code execution when…

  • CVE-2026-25105HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into parameters of the Modbus command tool in the debug route.

  • CVE-2026-25037HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by configuring a maliciously crafted LCD state which is later processed during system setup, enabling remote…

  • CVE-2026-24452HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices route.

  • CVE-2026-23702HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server username field of the import preconfiguration action in…

  • CVE-2026-20764HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by providing malicious input via the device hostname configuration which is later processed during system…

  • CVE-2026-25195HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via the firmware update route.

  • CVE-2026-25111HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the restore route.

  • CVE-2026-25109HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field when accessing the get setup route.

  • CVE-2026-24695HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into OpenSSL argument fields within requests sent to the utility route,…

  • CVE-2026-24689HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update apply action.

  • CVE-2026-24517HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the firmware update route.

  • CVE-2026-21389HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the request body sent to the contacts import route.

  • CVE-2026-20910HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update action to achieve remote code…

  • CVE-2026-20902HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filename field during the map upload action of the parameters…

  • CVE-2026-20742HigFeb 27, 2026
    risk 0.52cvss 8.0epss 0.01

    An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the templates route.

  • CVE-2025-52547HigSep 2, 2025
    risk 0.49cvss 7.5epss 0.00

    E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacker can use this command to continuously crash the application services.

  • CVE-2025-52545HigSep 2, 2025
    risk 0.49cvss 7.5epss 0.00

    E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password hashes for the application services.

  • CVE-2025-52544HigSep 2, 2025
    risk 0.49cvss 7.5epss 0.00

    E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can access any file from the E3 file system.

  • CVE-2025-52543HigSep 2, 2025
    risk 0.49cvss 7.5epss 0.00

    E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker can authenticate by obtaining only the password hash.

  • CVE-2025-52550HigSep 2, 2025
    risk 0.47cvss 7.2epss 0.00

    E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can install a malicious firmware upgrade.

  • CVE-2025-52546MedSep 2, 2025
    risk 0.40cvss 6.1epss 0.00

    E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can inject a stored XSS to the floorplan web page.

  • CVE-2025-52548MedSep 2, 2025
    risk 0.32cvss 4.9epss 0.00

    E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable…

  • CVE-2026-20797MedFeb 27, 2026
    risk 0.28cvss 4.3epss 0.01

    A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stack corruption and a termination of the program.

  • CVE-2026-22877LowFeb 27, 2026
    risk 0.24cvss 3.7epss 0.01

    An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to read arbitrary files on the system, and potentially causing a denial-of-service attack.